The CoconutWireless Network

Privacy Policy

The Coconut Wireless Network · Version 2.1 · Governed by the laws of Fiji

1. Introduction and Scope

This Privacy Policy explains what personal information the Coconut Wireless Network (the Platform) collects when you use our website and mobile apps, how we use and share it, and the choices and rights you have. It applies to clients, local professionals ("providers"), suppliers, and businesses who create an account or otherwise use the Platform.

This policy should be read together with our Terms & Conditions. Words defined there (such as "Provider" and "Client") have the same meaning here.

2. Information We Collect

2.1 Account information you provide

When you register, we collect your email address, password (stored in encrypted/hashed form, never in plain text), first and last name, mobile number, town/region, and date of birth; and, for users under 18, the name and contact details of a parent or guardian and a record of the consent given (including timestamp and IP address). If you sign in from the mobile app, we may store a device push-notification token (see 2.6) to deliver notifications, and a "keep me logged in" choice that extends how long your session stays active on that device.

2.2 Local professional (provider) information

If you register as a provider, we additionally collect your business or trading name, TIN, years of experience, bio, the trades/skills you offer, and the towns you service. To verify your credentials, we may collect documents such as your TIN letter, business licence, public liability insurance certificate, electrical contractor's licence, or plumber's licence, as applicable to your trade. These documents may contain government-issued identifiers and are used only for verification and stored securely — they are never shown publicly.

2.3 Supplier information

If you register as a supplier, we collect your business name, TIN, bio, the supply categories you offer, and the towns you service, along with verification documents such as your TIN letter and business registration. Supplier enquiries, quotes (including item lists and VAT/platform fee breakdowns), and in-Platform messages between clients and suppliers are also stored to operate that part of the Platform.

2.4 Task, quote, and messaging content

We collect the content you create while using the Platform: task descriptions, budgets, access notes, and photos you upload; quotes and in-Platform messages (with providers or suppliers); and public reviews and ratings. Message delivery and read status is recorded so you can see when a message has been seen. If you edit or delete a message, the previous version is kept internally (not shown to the other party) so a dispute or Platform Circumvention review always has the complete record. Where a provider leaves confidential feedback about a client, that feedback is used only by our team for account and dispute review — it is never shown publicly or to the client.

2.5 Billing and invoicing records

We keep internal records of platform fees and invoices (amounts in FJD, due dates, and payment status) to operate our billing. We do not collect or store payment card numbers or bank account details, and we do not process payments through the Platform — settlement between clients, providers, and suppliers, and payment of Platform fees, happens by arrangement outside the Platform, as described in our Terms.

2.6 Mobile app and push notifications

If you use our mobile app and enable notifications, we store a device push-notification token (via Firebase Cloud Messaging) so we can deliver you alerts about your tasks, quotes, and messages. You can disable this at any time in your device's notification settings.

2.7 Automatically collected information

When you accept our Terms, we record your IP address and browser/device user-agent string for legal record-keeping. We use only the cookies and session data necessary to keep you signed in and to protect against cross-site request forgery (see Section 11) — we do not use advertising, analytics, or tracking cookies or SDKs. If a technical error occurs, limited diagnostic information may be sent to our error-monitoring tool, which we configure to exclude personal information by default.

2.8 Information we do not collect

We do not collect precise GPS or device location — only the general town/region you select from a list. We do not use advertising or analytics tracking of any kind.

2.9 Linked and multi-role accounts

You can add more than one role to your account (for example, client and local professional), and you can link a second account you separately created. Linking only shares login access between the two accounts — it does not combine their information: each keeps its own email, password, and contact details, shown separately depending on which one you're using. You can unlink a login at any time from your account settings, provided at least one login remains active on the linked accounts.

3. How We Use Your Information

4. How We Share Your Information

We share information with other users only as necessary for the Platform to work — for example, a provider or supplier sees a client's task or enquiry details in order to quote on it, and a client sees a provider's or supplier's public profile, quotes, and reviews.

We share information with service providers who process it on our behalf, limited to what they need to provide their service:

Service provider typePurpose
Cloud hostingRunning the Platform's website and mobile app backend
Object storage providerStoring uploaded photos and verification documents
Email delivery providerSending account and transactional emails
Push notification service (Firebase)Delivering mobile app notifications, if enabled
Error-monitoring toolDiagnosing technical faults; configured to exclude personal data by default

We may also disclose information where required by law, to protect our legal rights, or to protect the safety of our users. We do not sell your personal information, and we do not share it with third parties for their own advertising or marketing purposes.

5. Data Retention

We keep your information for as long as your account is active, and afterward for as long as reasonably necessary to meet legal, tax, accounting, or dispute-resolution obligations. Verification documents are retained only as long as needed for verification and compliance purposes. Message edit history is retained for dispute/Platform Circumvention review as described in Section 2.4. If you delete your account, we remove or anonymize personal information that we are not otherwise required to keep, within a reasonable time.

6. Data Security

We use industry-standard safeguards to protect your information, including encrypted connections (HTTPS), access controls limiting who on our team can view sensitive data, and private, non-public storage for verification documents. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

7. Your Rights and Choices

You can review and update most of your account and profile information at any time by logging in. You can disable push notifications from your device settings. Depending on where you're located, you may have additional rights under applicable data protection law — for example, to request a copy of your data, correction, restriction of processing, or to object to certain uses. Contact us (Section 14) and we will respond in accordance with applicable law.

8. Account and Data Deletion

You can delete your account at any time from your account settings, or by contacting us through our Support page. We will delete or anonymize your personal information within a reasonable time, except where we are required or permitted by law to retain certain records — for example, financial and invoicing records, or records relevant to an active dispute, investigation, or Platform Circumvention case.

If you've linked a second account (Section 2.9), deleting one account deletes only that account's own information — any other account still linked to it, and its data, is not affected and remains active on its own login.

9. Children's and Minors' Privacy

The Platform may be used by persons aged 16 and over. We do not knowingly collect personal information from anyone under 16; if we learn that we have, we delete it.

For users aged 16 or 17 (Minor Users):

All users' dates of birth are used to determine age-appropriate treatment on the Platform and are never displayed publicly.

10. International Data Transfers

Our hosting, storage, and other service providers may process your information outside Fiji, in countries where they operate their infrastructure. By using the Platform, you understand that your information may be transferred to and processed in those countries, and we take reasonable steps to ensure it continues to be protected wherever it is processed.

11. Cookies and Sessions

We use only the cookies and session mechanisms necessary for the Platform to work: a session cookie that keeps you signed in (extended if you choose "keep me logged in"), and a security cookie that protects against cross-site request forgery. We do not use advertising, analytics, or third-party tracking cookies.

Sponsor banners or business profiles may link to third-party websites. We are not responsible for the privacy practices of those third-party sites — please review their own privacy policies.

13. Changes to This Policy

We may update this policy from time to time. If we make material changes, we will notify you — for example, by posting a notice on the Platform or sending an email — before the changes take effect.

14. Contact Us

Questions about this policy, or requests relating to your personal information (access, correction, or deletion), can be sent via our Support page.

The Coconut Wireless Network · Fiji · Version 2.1 · For questions contact us via the Platform.